avast says "Windows/Assembly/GAC_64/Desktop.ini" (Same goes for _32) is infected

Avast says Windows/Assembly/GAC_64/Desktop.ini and Windows/Assembly/GAC_32/Desktop.ini is infected i delete them Avast says they are gone I restart than they are back even when they are deleted with a boot scan. Also windows defender says i have Trojan:Win32/Sirefef.AB so i delete that to restart its back.

siref mean ZeroAccess rootkit

follow this guide and attach (not copy and paste) logs from Malwarebytes / OTL / aswMBR
http://forum.avast.com/index.php?topic=53253.0

when done a malware removal specialist will be notified… it may take several hours befor he arrive so be patient

Ok here are the logs.

malwarebytes was not updated when you did the scan…
always click the update button before a scan so that you are scanning with latest signatures, MBAM release 5 - 10 updates a day

you dont have to post a new log unless anything is detected :wink:

and your aswMBR log say siref infection…meaning ZeroAccess rootkit

the malware remover is notified :wink:

thanks I will remember to always update. It was still clean btw.

open malwarebytes > settings > warn if database is outdated by ( days ) sett it to 1…in case you forget :wink:

Hi,

Just so you know I will be limited tonight (CST)…

WARNINGUnfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

Unfortunately I have found what is known as the ZeroAccess rootkit on your system. It is an especially nasty infection that can take quite some time to clean as well as may have damaged your system files itself. As a warning, during the cleaning (if you choose to do so) you may lose internet access with this computer and in the end we may need to reinstall the operating system anyway depending on the extent of the infection.

If you would like to format and reinstall your Operating System please let me know and we can assist you with that.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help. :slight_smile:

Please double click the aswMBR icon to run it.
Vista and Windows 7 users right click the icon and choose “Run as administrator”.

[*]Click the Scan button to start scan.
[*]When scan finishes, press the Fix Button. Once the Fix is done, press the Save Log button and save the log to your desktop. You need to reboot your computer when its done before you do anything else, then post the log that will be on your desktop.


http://i1190.photobucket.com/albums/z454/Blottedisk/aswMBRfix-1.png

Click the image to enlarge it

do you think it would be safe for me to backup pics and files of that sort on my extern hd i have or could the virus put it self on it?
edit : scanned clicked fix twice by accident saved log then restarted:

Hi,

Yes it is safe to save your files. Be sure to only save files such as pics, personal files, docs, music…just no actual programs.

Please run a new scan with aswMBR.exe and then attach the new log.

ok so I changed my mind and started wiping my pc but ran into a problem the disks i got with my pc that i was told would wipe my pc and reinstalling win 7 only did the wiping part and i dont have a win 7 dvd or back up dvd so can you help? :-\

edit found the cd but it says unable to find or create partion at where to install Win7 stage formatted it but still wont install.

I am not a super tech person so I will guide you to here so you can look through it and be sure you got everything covered since you are doing a reinstall. >> http://howtoformatacomputer.com/format-windows-7